SLIDE 10 List decoding of the First order Reed-Muller codes Application to cryptanalysis PA Attacks overview Ideal Countermeasure MLPA Approximation of a bloc cipher
Results for 8 rounds of DES
Bias ×104 Linear Combination −2.49 PH[15]⊕ PL[0, 7, 18, 24, 31] ⊕ K[4, 9, 13, 31, 33, 41, 44, 52, 54] 4.86 PH[15]⊕ PL[0, 7, 18, 24, 27, 31] ⊕ K[4, 9, 13, 31, 33, 41, 44, 47, 52, 54] −4.68 PH[15]⊕ PL[0, 7, 18, 24, 28] ⊕ K[4, 9, 15, 31, 33, 41, 44, 52, 54] 4.81 PH[15]⊕ PL[0, 7, 18, 24, 27, 28] ⊕ K[4, 9, 15, 31, 33, 41, 44, 47, 52, 54] −2.18 PH[15]⊕ PL[0, 7, 18, 24, 27, 28, 29, 31] ⊕ K[9, 13, 15, 31, 33, 41, 44, 47, 52, 54] −3.67 PH[15]⊕ PL[0, 7, 18, 24, 27, 28, 31] ⊕ K[4, 9, 13, 15, 31, 33, 41, 44, 47, 52, 54] −4.59 PH[15]⊕ PL[0, 7, 18, 24, 30] ⊕ K[4, 9, 30, 31, 33, 41, 44, 52, 54] 2.63 PH[15]⊕ PL[0, 7, 18, 24, 27, 30] ⊕ K[4, 9, 30, 31, 33, 41, 44, 47, 52, 54] 2.3 PH[15]⊕ PL[0, 7, 18, 24, 29, 30, 31] ⊕ K[9, 13, 30, 31, 33, 41, 44, 52, 54] 2.69 PH[15]⊕ PL[0, 7, 18, 24, 27, 29, 30, 31] ⊕ K[9, 13, 30, 31, 33, 41, 44, 47, 52, 54] 3.77 PH[15]⊕ PL[0, 7, 18, 24, 30, 31] ⊕ K[4, 9, 13, 30, 31, 33, 41, 44, 52, 54] 3.23 PH[15]⊕ PL[0, 7, 18, 24, 27, 30, 31] ⊕ K[4, 9, 13, 30, 31, 33, 41, 44, 47, 52, 54] 2.43 PH[15]⊕ PL[0, 7, 18, 24, 27, 28, 29, 30] ⊕ K[9, 15, 30, 31, 33, 41, 44, 47, 52, 54] −3.33 PH[15]⊕ PL[0, 7, 18, 24, 28, 30] ⊕ K[4, 9, 15, 30, 31, 33, 41, 44, 52, 54] −3.13 PH[15]⊕ PL[0, 7, 18, 24, 28, 29, 30, 31] ⊕ K[9, 13, 15, 30, 31, 33, 41, 44, 52, 54] 4.52 PH[15]⊕ PL[0, 7, 18, 24, 28, 30, 31] ⊕ K[4, 9, 13, 15, 30, 31, 33, 41, 44, 52, 54] 2.05 PH[15]⊕ PL[7, 18, 24, 27, 31] ⊕ K[4, 9, 13, 31, 33, 41, 44, 47, 52] 2.48 PH[15]⊕ PL[7, 18, 24, 27, 28, 30, 31] ⊕ K[4, 9, 13, 15, 30, 31, 33, 41, 44, 47, 52] 4.82 PH[15]⊕ PL[7, 18, 24, 31] ⊕ K[4, 9, 13, 31, 33, 41, 44, 52] 2.05 PH[15]⊕ PL[7, 18, 24, 27, 31] ⊕ K[4, 9, 13, 31, 33, 41, 44, 47, 52] 2.49 PH[15]⊕ PL[7, 18, 24, 28, 29, 31] ⊕ K[9, 13, 15, 31, 33, 41, 44, 52] −3.4 PH[15]⊕ PL[7, 18, 24, 27, 28, 31] ⊕ K[4, 9, 13, 15, 31, 33, 41, 44, 47, 52] 3.55 PH[15]⊕ PL[7, 18, 24, 29, 30] ⊕ K[9, 30, 31, 33, 41, 44, 52] −2.31 PH[15]⊕ PL[7, 18, 24, 27, 30] ⊕ K[4, 9, 30, 31, 33, 41, 44, 47, 52] 2.28 PH[15]⊕ PL[7, 18, 24, 27, 28, 29, 30] ⊕ K[9, 15, 30, 31, 33, 41, 44, 47, 52] 5.83 PH[15]⊕ PL[7, 18, 24, 27, 28, 29, 30, 31] ⊕ K[9, 13, 15, 30, 31, 33, 41, 44, 47, 52]
Tab.: Ciphertext bits combination : CL[12, 16] ⊕ CH[7, 18, 24]